Centralized Access Control List for Multi-Source Data Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data analytics systems face challenges in managing authentication and authorization for requesting devices accessing multiple data sources, leading to complex and insecure access management, where requesting devices are burdened with unique access management and security vulnerabilities arise due to pass-through authentication methods.

Innovation Solution

A data analytics system that synchronizes access rule sets and identifiers from multiple data sources, generating a centralized access control list to manage access permissions, reducing the need for individual access management by requesting devices and enhancing security by maintaining access permissions at a centralized system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If pass-through authentication is used where requesting devices maintain unique access to each data source, then each requesting device can access data from multiple data sources, but the system complexity increases and security vulnerabilities arise

Engineering Contradiction:
Improveaccess capability to multiple data sourcesVSAvoidauthentication management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The data analytics system acts as an intermediary between requesting devices and data sources. It obtains access rule sets from multiple data sources, synchronizes them into a unified access control list, and manages authentication centrally. This eliminates the need for requesting devices to individually manage unique access to each data source, reducing complexity while maintaining security through centralized permission enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the data analytics system authenticates itself with each data source to relieve burden on requesting devices, then requesting devices have simplified access, but security vulnerabilities arise allowing unauthorized access

Engineering Contradiction:
Improveaccess management ease for requesting devicesVSAvoidsecurity of data source access
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The data analytics system serves as a security intermediary by obtaining and synchronizing access rule sets from data sources. It maintains a centralized access control list that enforces permission checks before granting access to aggregated data. This approach simplifies operations for requesting devices while preserving security through centralized authorization management, preventing unauthorized access even when the analytics system acts as intermediary.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If individual authentication and authorization is handled for each data source access, then precise access control is maintained, but processing costs and system overhead increase

Engineering Contradiction:
Improveaccess permission control accuracyVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The data analytics system performs preliminary actions by obtaining access rule sets from multiple data sources in advance and synchronizing them into a unified access control list. This pre-processing of authorization information allows the system to make rapid access decisions without performing individual authentication checks for each data source access request, thereby maintaining precise access control while significantly improving processing efficiency.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11921869B1Authorization methods and systems for accessing multiple data sources
Publication Date: 2024.03.05 SEEQ CORP
  • US11921869B1 patent drawing
  • US11921869B1 patent drawing
  • US11921869B1 patent drawing

AI summary

A data analytics system to authenticate and authorize access to multiple sources of data for access to the multiple data sources for one or more requesting devices. The system may duplicate and/or access rule sets included in the metadata of the corresponding data source and read identifiers of authorized users maintained by each of the multiple data sources. The access rule sets and authenticated identifiers may be synchronized or otherwise correlated to requesting device identifiers maintained by the data analytics system such that, as requests to access data obtained from one or more of the multiple data sources are received, the system may control access to or otherwise manage the requesting devices interactions with the data from the multiple data systems, reducing the authorization and authentication actions needed to be taken or executed by the requesting devices and the data sources.